The README, changelog, repository tests, and MIT licensing provide a clear starting point for integration. However, the project has had no commits or releases since June 2023, and its workflow uses three unpinned actions without a security policy, making ongoing maintenance and build hygiene weak.
43%
Total Score
25
100
72
75
Only two releases were published, both in June 2023, with none in the last 12 months and roughly three years since the latest release. This is strong evidence of an inactive project for a package developers may need to maintain.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in June 2023. This materially raises abandonment risk.
The package and repository are owned by individual accounts rather than an organization, so continuity depends on a narrow ownership base. This reinforces the maintenance concern but is not itself proof of abandonment.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these figures provide no supporting evidence of a maintained user base.
Composer is used for the build, but no security scanning tools are present. The missing scanning is a modest hygiene gap, especially alongside the long maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.